FLAC records
6 published records for vendor flac.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-189 Numeric Errors1
- CWE-20 Improper Input Validation1
- CWE-399 Resource Management Errors1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2007-4619No exploit | Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow flac · libflac · CWE-189 | Critical9.3 | — | 6.7% | Oct 12, 2007 |
39Monitor | CVE-2007-6277No exploit | Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitraryflac · libflac · CWE-119 | Critical9.3 | — | 6.7% | Dec 7, 2007 |
38Monitor | CVE-2007-6279No exploit | Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to executflac · libflac · CWE-399 | Critical9.3 | — | 4.0% | Dec 7, 2007 |
38Monitor | CVE-2007-6278No exploit | Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files viflac · libflac · CWE-20 | Critical9.3 | — | 2.1% | Dec 7, 2007 |
33Monitor | CVE-2014-8962No exploit | Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flaflac · libflac · CWE-119 | High7.5 | — | 9.9% | Nov 26, 2014 |
33Monitor | CVE-2014-9028No exploit | Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flacflac · libflac · CWE-119 | High7.5 | — | 9.8% | Nov 26, 2014 |
- CVE-2007-461939Monitor
Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow
CriticalCVSS 9.3No exploitEPSS 7%flac · libflacOct 12, 2007
- CVE-2007-627739Monitor
Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary
CriticalCVSS 9.3No exploitEPSS 7%flac · libflacDec 7, 2007
- CVE-2007-627938Monitor
Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execut
CriticalCVSS 9.3No exploitEPSS 4%flac · libflacDec 7, 2007
- CVE-2007-627838Monitor
Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files vi
CriticalCVSS 9.3No exploitEPSS 2%flac · libflacDec 7, 2007
- CVE-2014-896233Monitor
Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .fla
HighCVSS 7.5No exploitEPSS 10%flac · libflacNov 26, 2014
- CVE-2014-902833Monitor
Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac
HighCVSS 7.5No exploitEPSS 10%flac · libflacNov 26, 2014